Alert Service

National Cyber-​​Alert Sys­tem: NTP Alert (2009−3563)

Overview ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attack­ers to cause a denial of ser­vice (CPU and band­width con­sump­tion) by using MODE_​​PRIVATE to send a spoofed (1) request or (2) response packet that trig­gers a con­tin­u­ous exchange of MODE_​​PRIVATE error responses between two NTP dae­mons. Impact CVSS Sever­ity (ver­sion 2.0): CVSS v2 Base Score:6.4 (MEDIUM) […]

Alert Service

National Cyber-​​Alert Sys­tem: NTP Alert (2009−1252)

CERT Alert for NTP Ver­sions before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSL and autokey are enabled. This directly impacts PCI DSS com­pli­ance prac­tices using NTP with OpenSSL and autokey to iden­tify end-​​​​nodes in NTP ser­vice topolo­gies. CERT 2009–1252

Downloads

PCI DSS 6.1 Alert for 10.4 com­pli­ance … NTP Secu­rity Hole Patched

PCI DSS — 10.4 Com­pli­ance Alert — NTP Flaws require imme­di­ate attention.